CVE-2025-26516: Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)
Published Sep 19, 2025
·Updated
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Service vulnerability. Successful exploit could allow an unauthenticated attacker to cause a Denial of Service on the Admin node.
Affected Software
3 affected components
NetApp Storagegrid<11.8.0.15, <11.9.0.8
NetApp Storagegrid<11.8.0.15
NetApp Storagegrid>=11.9.0<11.9.0.8
Event History
Sep 19, 2025
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26516?
CVE-2025-26516 is classified as a Denial of Service vulnerability.
2
How do I fix CVE-2025-26516?
To mitigate CVE-2025-26516, upgrade to NetApp StorageGRID versions 11.8.0.15 or 11.9.0.8 or later.
3
Who is affected by CVE-2025-26516?
CVE-2025-26516 affects users of NetApp StorageGRID versions prior to 11.8.0.15 and 11.9.0.8.
4
Can CVE-2025-26516 be exploited remotely?
Yes, CVE-2025-26516 can be exploited by unauthenticated attackers to cause a Denial of Service on the Admin node.
5
What types of attacks does CVE-2025-26516 enable?
CVE-2025-26516 enables Denial of Service attacks against the affected NetApp StorageGRID instances.